Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 222

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Palantir rallies 15% for the week as Iran war boosts prospects, muting Anthropic concern
Berkshire CEO Greg Abel on working with Buffett, Kraft Heinz and using all his salary to buy the stock
Google joins Microsoft in telling users Anthropic is still available outside defense projects
Here are 3 themes that drove another challenging week on Wall Street
Middle-income homebuyers have $30,000 more buying power than a year ago, research finds. It's still not enough
Macros Diet App
US citizens using a passport card instead of book?
Looking for custom muscian's earplugs in Toronto
FDA vaccine head will step down in April after string of controversial decisions
This homebuilding play is one of the most oversold stocks amid this week’s market turmoil